We aim to use personal information fairly, transparently, and only for legitimate purposes. This Policy should be read with our Terms of Use and any privacy notice presented when a specific service is offered.
1. Who we are and the scope of this Policy
Dar Al Tharwah operates this website and related member, educational, newsletter, consultation, course, and download services. “Dar Al Tharwah”, “we”, “us”, and “our” refer to the business operating the relevant service and the entity identified in a written engagement, invoice, or checkout where applicable.
This Policy applies to information processed through the public website, member accounts, profile pages, authentication, enrolment and access controls, newsletters, consultation requests, forms, communications, and related digital services. A separate professional engagement may include additional privacy information.
2. Information we may collect
- Identity and profile information: first name, last name, account name, country, and preferred language.
- Contact information: email address, phone number, and communication preferences.
- Account and authentication information: account identifiers, login and logout events, session or security data, verification status, and records needed to protect access. Passwords should be stored only in protected form by the authentication system and are not displayed to Dar Al Tharwah staff.
- Membership and learning activity: registrations, enrolments, course or download access, content keys, newsletter status, and account activity required to provide member resources.
- Consultation information: messages, questions, goals, contact preferences, and financial or personal context you choose to provide when requesting guidance.
- Communications: messages sent through forms, responses, support requests, and records of our communications with you.
- Technical and usage information: IP address, browser, device, operating system, pages visited, timestamps, referral information, language, security logs, and similar diagnostic data where collected by the website or service providers.
- Preference data: language and interface choices, including a light or dark theme preference stored locally in your browser.
- Transaction information: where paid services are offered, purchase, billing, tax, and payment-status information. Payment credentials may be processed directly by a payment provider identified at checkout.
3. How we collect information
We collect information directly when you create or update an account, log in, enrol, unlock a resource, subscribe, submit a consultation or contact form, communicate with us, or make a purchase. We also receive limited technical and security information automatically from your browser, device, cookies, local storage, logs, and service providers.
We may receive information from a professional adviser, business partner, event organiser, referral source, or publicly available source only where lawful and relevant. Where required, we will tell you the source and provide the necessary privacy information.
4. Why we use personal information
Depending on the service and applicable law, we process information to perform a contract, take requested pre-contract steps, obtain and respect consent, comply with legal duties, and pursue legitimate interests that do not override your rights.
- create, authenticate, secure, and administer member accounts;
- provide enrolment, courses, downloads, newsletters, consultation requests, profile management, and customer support;
- respond to questions and prepare or deliver a requested professional service;
- process purchases, prevent fraud, maintain records, and meet accounting or legal obligations where paid services are offered;
- send essential account, security, service, and transaction communications;
- send optional newsletters or marketing where you have consented or where another lawful basis permits it;
- measure and improve accessibility, performance, content, reliability, and user experience;
- detect, investigate, and prevent abuse, security incidents, unlawful activity, and violations of our Terms;
- establish, exercise, or defend legal claims and comply with lawful requests.
5. Membership, authentication, and access records
The membership system uses account and session information to determine whether a visitor is signed in, enrolled, or authorised to access a course, download, dashboard, profile, newsletter action, or consultation submission. We use these records to provide the requested service and protect restricted content.
We do not currently use solely automated decision-making that produces legal or similarly significant effects. Automated access checks only determine whether account, enrolment, or content-access conditions are met. We will update this Policy before introducing materially different automated decision-making where notice is required.
6. Consultation and financial information
You may choose to provide information about your financial goals, income, assets, liabilities, family priorities, property, retirement, education, business, or investment interests during a consultation process. Provide only information relevant to your request and do not submit account passwords, private keys, complete payment-card details, or unnecessary identity documents through ordinary website forms.
Submitting consultation information does not itself create an adviser-client or fiduciary relationship. Where a professional engagement begins, its agreement may describe additional information, confidentiality duties, retention requirements, and service-specific processing.
7. Cookies, local storage, and similar technologies
The website may use cookies, browser storage, and similar technologies for authentication, session continuity, account security, language handling, interface preferences, fraud prevention, diagnostics, and—where enabled—analytics or performance measurement.
The current theme preference is stored in browser local storage under a site-specific key so the light or dark appearance can be remembered. Necessary technologies may operate without optional consent where permitted. Where law requires consent for optional analytics or marketing technologies, we will request it before use and provide a way to change the choice.
8. When we share information
We do not sell personal information. We may share only what is reasonably necessary with:
- hosting, database, authentication, security, form, email, newsletter, analytics, customer-support, file-delivery, and payment providers;
- professional advisers, auditors, insurers, and contractors bound by appropriate confidentiality duties;
- a relevant Dar Al Tharwah service entity where needed to provide the requested service;
- courts, regulators, law-enforcement bodies, or other authorities where disclosure is required or lawfully requested;
- a buyer, investor, successor, or restructuring participant where a business transaction requires controlled due diligence and appropriate safeguards.
Providers may process information only for agreed services and under contractual or legal safeguards appropriate to their role.
9. International transfers
Dar Al Tharwah serves users across the Middle East and has operational contact points in Oman and the United Kingdom. Service providers may process information in other countries. Where personal information is transferred internationally, we use the safeguards required by applicable law, such as an adequacy mechanism, contractual protection, consent where valid, or another lawful transfer basis.
10. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose collected, including providing an active account or service, responding to requests, maintaining security, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, or regulatory obligations.
Retention periods depend on the type of information, sensitivity, risk, service relationship, legal requirements, and whether the information can be securely deleted or anonymised. Account information may be retained while the account remains active and for a limited period afterward; consultation and transaction records may be retained longer where necessary for professional, legal, or financial recordkeeping.
11. Security
We use reasonable technical and organisational measures intended to protect personal information, including access controls, authentication, secure hosting practices, restricted staff access, monitoring, and provider due diligence where appropriate. No internet service or storage system can be guaranteed completely secure.
If a personal-data breach creates a legal notification duty, we will notify the competent authority and affected individuals as required by applicable law.
12. Your privacy rights
Depending on applicable law and the circumstances, you may have the right to:
- receive clear information about processing;
- request access to personal information held about you;
- correct or update inaccurate or incomplete information;
- request deletion where there is no continuing lawful reason to retain the information;
- restrict or object to certain processing;
- receive portable information where the legal conditions apply;
- withdraw consent without affecting processing already carried out lawfully;
- object at any time to direct marketing;
- complain to the competent data-protection or consumer authority.
We may verify identity before fulfilling a request and may retain information where law, security, fraud prevention, legal claims, or another valid basis requires it. We will explain any lawful limitation.
13. Marketing choices
You can unsubscribe from optional newsletters or marketing by using the unsubscribe method in the message or contacting us. Withdrawing marketing consent does not stop necessary account, security, service, or transaction messages.
14. Children
The member and consultation services are not directed to children under 18. A parent or legal guardian must provide any required authorisation for a permitted educational activity involving a minor. If we learn that a child’s information was collected without required authority, we will take appropriate steps to delete or lawfully regularise it.
15. Third-party websites and services
Links or embedded services operated by others are governed by their own privacy practices. Review their notices before providing information. Dar Al Tharwah is not responsible for independent third-party processing outside our control.
16. Changes to this Policy
We may update this Policy when services, providers, law, or processing activities change. We will revise the effective date and communicate material changes to registered users through a reasonable channel before the new use begins where required.
17. Contact and privacy requests
To ask a privacy question, exercise a right, withdraw consent, or request account closure, use the contact and consultation page and clearly state that the message is a privacy request. You may also contact the published phone or WhatsApp numbers:
Oman OfficeOminvest Business Center, Muscat Hills
H7FW+MW7, Muscat, Sultanate of Oman
+968 9781 3737
+968 9779 2603UK Registered Office
71–75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
You may also complain to the competent authority in the country where you live, work, or believe a violation occurred. Where UK data-protection law applies, this may include the UK Information Commissioner’s Office. Where Oman law applies, rights and complaints are handled under the Personal Data Protection Law and its executive regulation.
.avif)